Skip to main content
Legal

Privacy notice

This notice describes the data the current application stores and why. It is based on the implemented account, test, analytics and billing models.

Effective 11 August 2026

Account data

The application stores your name, email address, identity-provider user reference, verification and login timestamps, chosen exam, content-language preference and onboarding choices. The identity provider handles credentials and sessions; Abhyaas does not store your password.

Practice and analytics data

We store attempts, saved answers, timing and navigation events, submission status, scores, section and topic performance, result history and leaderboard records. This is used to deliver and score tests, resume an attempt, show your history, enforce the attempt limits and cooldowns each certification states, and calculate analytics supported by real attempts.

Billing data

The application stores which certifications you have bought, the amount and currency charged, the purchase date and status, the payment provider’s payment and customer references, invoice records, and an audit trail of changes to any of it. Card and bank details are handled by the payment provider and are never stored in the Abhyaas database.

Providers

The current architecture uses WorkOS for identity, Dodo Payments for hosted billing and Cloudflare for application hosting and database infrastructure. Each provider may process the information needed to perform its service. Their own notices govern data they collect directly.

Sharing controls

Public result sharing is off until you enable it for a result. Leaderboard display has a separate anonymity preference. Do not treat either control as a substitute for keeping your account credentials private.

Cookies and security records

Session cookies keep you signed in, a locale cookie remembers interface language, and CSRF tokens protect state-changing requests. Security and rate-limit records use hashed identifiers or network buckets rather than storing a raw password or payment credential.

Retention and account closure

Attempt, result, billing and audit records are designed to remain internally consistent. The data model supports anonymising an account instead of deleting linked records, but the current product has no public request channel or self-service closure control. No retention period is claimed until the operator publishes one with its legal identity and privacy contact.